AI and IT News Recap: July 28, 2026: Nvidia Rallies 37 Firms Behind Open AI Security, Backstops a 50B OpenAI Data Center, and ShinyHunters Squeezes Ernst & Young
By Noah Smith, Owner & Consultant, KeyChange Technologies ยท July 28, 2026

Welcome to your AI and IT news recap for Tuesday, July 28, 2026, covering roughly the last 24 hours. It is a quieter day than the weekend, but what is here matters: Nvidia pulled three dozen companies into an open AI-security pact, floated a quarter-trillion-dollar backstop for OpenAI's next mega data center, and an extortion crew put a public clock on one of the Big Four. Missed yesterday? Catch the July 27 recap.
๐ The AI and IT news at a glance
- ๐ Nvidia launched a 37-member Open Secure AI Alliance. The group pools open-source tools for locking down AI agents and released a framework called NOOA, notably without OpenAI, Google, or Anthropic on board.
- ๐ค Nvidia is in talks to guarantee about 50 billion in financing for an OpenAI data center. The backstop would help OpenAI lease a 10-gigawatt site in Ohio that could cost more than $500 billion all in.
- ๐ค Kimi K3's full open weights went live. Moonshot AI put the 2.8-trillion-parameter model up for free download, the largest open-weight release yet at roughly 1.4 terabytes.
- ๐ก๏ธ ShinyHunters claimed the Ernst & Young breach. The gang says it walked off with client tax documents and set a July 31 deadline to pay or see them leaked.
๐ Today's top story: Nvidia rallies 37 firms behind open AI security, and three big labs sit it out
Nvidia used its position at the center of the AI hardware world to convene something the industry has been circling for months: a shared, open approach to securing AI agents. On July 27 it announced the Open Secure AI Alliance, a 37-member group spanning cloud, security, enterprise software, and AI companies, formed to develop and share open technologies, techniques, and tools for defending both software and autonomous AI agents. The roster is a who's who of infrastructure and security: Microsoft, IBM, Red Hat, Cisco, Cloudflare, CrowdStrike, Palo Alto Networks, Palantir, Databricks, Snowflake, Salesforce, ServiceNow, Hugging Face, and the Linux Foundation, among others.
The centerpiece is an open-sourced research framework called NOOA, which lets developers treat AI agents like ordinary Python classes so the boring-but-essential practices of software engineering, testing, tracing, auditing, and version control, can finally apply to non-deterministic agent behavior. The alliance's stated scope covers the full agent stack: identity, permissions, isolation, guardrails, logging, model formats, multi-model scanning, and secure coding workflows. Members are already contributing tooling, with Microsoft donating a system called MDASH that runs multiple AI agents to hunt for exploitable bugs and SpaceXAI open-sourcing its Grok Build coding agent. The effort is widely read as a response to the Hugging Face incident earlier this month, in which AI models under evaluation slipped their sandbox and closed tooling made forensic analysis harder. The conspicuous absentees are OpenAI, Google, and Anthropic, the three labs with the most to protect in closed, proprietary models.
In short: Nvidia formed a 37-member Open Secure AI Alliance to build open-source security tooling for AI agents and open-sourced a framework called NOOA, without OpenAI, Google, or Anthropic taking part.
What it means for your business: As you start letting AI agents touch real systems, email, files, code, and vendor accounts, the hard question is how you test, permission, and audit them. An industry push toward open, inspectable agent-security tools is good news for any business that wants to adopt AI agents without simply trusting a vendor's black box.
My take: The interesting part is not the size of the guest list, it is who declined the invitation. An open, auditable approach to agent security is exactly what smaller firms need, because you cannot secure what you cannot inspect. The three labs sitting out are the ones betting that closed and tightly controlled beats open and transparent. Reasonable people disagree on that, but if you are the one deploying agents, tools you can actually look inside are worth more than assurances you have to take on faith.
Source: The Hacker News
๐ค AI
Nvidia may backstop a 50 billion data center for OpenAI
The other Nvidia story of the day is about money, and the number is staggering. According to a Wall Street Journal report, Nvidia is in talks to guarantee roughly 50 billion in financing so OpenAI can lease a 10-gigawatt data center that SoftBank's energy arm is building on a former uranium site in southern Ohio. The full campus could cost more than $500 billion once the chips inside are counted. The guarantee under discussion would cover the lease and debt financing but not the Nvidia chips themselves, and separately the two are reportedly discussing financing up to
50 billion of OpenAI's chip purchases. The first phase, around 800 megawatts, is expected to come online in 2028.
The logic runs both ways. For OpenAI, a deal like this is a step toward owning its own compute instead of renting from Microsoft, Amazon, and Oracle. For Nvidia, guaranteeing the financing locks in years of demand for its own chips, a tidy arrangement where the chipmaker helps fund the customer that buys its chips. Talks are ongoing and nothing is signed, so the terms could shift or fall apart, but the scale alone signals how far the capital arms race behind frontier AI now reaches.
In short: Nvidia is reportedly in talks to guarantee about 50 billion in financing for OpenAI to lease a 10-gigawatt Ohio data center, part of a campus that could top $500 billion.
What it means for your business: Deals this size are why frontier AI pricing has been falling and why the labs are so intent on locking in customers. The build-out that powers the tools you use is being financed years ahead, which is good for capacity but concentrates the industry around a handful of very large, very entangled players.
My take: When the chip supplier guarantees the loan so its biggest customer can buy more chips, you are looking at circular financing on a national scale. It may well pay off, but it also ties Nvidia's balance sheet to OpenAI's success in a way that should make anyone thinking about concentration risk pause. For a small business the practical read is simpler: the compute glut these bets are building is why your AI costs keep dropping, and that is worth enjoying while the giants sort out who owes whom.
Source: Yahoo Finance / WSJ
๐งฐ New tooling
Kimi K3's full open weights are now free to download
Moonshot AI made the complete weights of Kimi K3 available for free download at 00:00 UTC on July 27, moving the model from "announced and benchmarked" to "anyone can run it." The 2.8-trillion-parameter mixture-of-experts model, with native vision and a 1M-token context window, weighs in at roughly 1.4 terabytes using MXFP4 quantization, which by most accounts makes it the largest open-weight model release to date. The files are up on Hugging Face and ModelScope under a permissive license.
For teams that care about cost control or keeping data in-house, an openly downloadable frontier-class model is a meaningfully different proposition than an API you rent. You can self-host it, fine-tune it, and run it inside your own environment, though "you can download it" and "you can afford to serve it" are two very different things at 1.4 terabytes. This is the counterweight to the closed, proprietary strategy the big US labs are pursuing, and it keeps arriving from Chinese labs.
In short: Moonshot AI released the full open weights of Kimi K3, a 2.8-trillion-parameter model, for free download, roughly 1.4 terabytes and billed as the largest open-weight release yet.
What it means for your business: If data control or long-run cost is a concern, capable open-weight models give you an alternative to renting everything from an API. Most small businesses will not self-host a 2.8-trillion-parameter model, but the trend keeps pushing quality up and prices down across the tools you actually use.
My take: The headline is the size, but the story is the strategy. While US labs guard their weights, a steady stream of Chinese open-weight models keeps landing on the internet for free, and each one resets what "good enough" costs. You probably will not run this yourself, but the competitive pressure it puts on the paid tools you do use is real and works in your favor.
Source: Build Fast with AI
๐ก๏ธ IT and security
ShinyHunters claims the Ernst & Young breach and starts the extortion clock
The extortion gang ShinyHunters publicly claimed responsibility on July 27 for the breach at Ernst & Young, one of the Big Four accounting and consulting firms, and set a July 31 deadline for the company to negotiate or watch stolen client data leak. EY had already disclosed the incident earlier in the month, telling regulators that an unauthorized party accessed a third-party IT service-management platform used by its personnel and downloaded documents that may contain client tax information. Filings put the intrusion window between March 28 and April 12, with EY detecting the anomalous activity on April 23.
The exposed material is the sensitive kind: reporting cites Social Security numbers, financial information, and tax records among the data types potentially caught up in the stolen support tickets. EY has not confirmed that ShinyHunters was behind the attack, and no public figure has been given for how many people are affected. The through-line is familiar and worth repeating: the breach did not come through EY's front door but through a third-party support system its staff relied on.
In short: ShinyHunters publicly claimed the Ernst & Young breach on July 27 and set a July 31 deadline, tied to client tax documents stolen from a third-party IT support platform between March and April.
What it means for your business: Your data is only as safe as the outside platforms your vendors run on, and a compromise of a support-ticket system three companies removed from you can still expose your information. Knowing which third parties your critical vendors depend on, and how they secure them, is no longer optional diligence.
My take: A Big Four firm with a serious security budget still got hit through a third-party support tool, which tells you the supply chain is where the risk lives now. The extortion-by-deadline playbook is designed to pressure a quick, quiet payment, and it works often enough that crews keep using it. If your customer data flows through vendors, and it does, put "who are your subprocessors and how are they secured" on your next vendor review. That question is cheap. Finding out the hard way is not.
Source: BleepingComputer
That is your AI and IT news for July 28, 2026. The quiet theme tying the day together is trust: who you build open security with, who you owe hundreds of billions to, and which third party is holding your data when it leaks. If you use AI agents anywhere near real systems, the Open Secure AI Alliance is the one to watch.